Enhancing Multipath TCP Security Through Software Defined Networking

Reem Melki, Ali Hussein, Ali Chehab · 2019

Multipath TCP (MP-TCP) has been introduced as an extension to legacy TCP to support simultaneous communication through multiple paths. Although MP-TCP has many advantages over TCP, some issues and challenges related to security robustness of this protocol remain unaddressed. The root cause of many threats specific to MP-TCP stem from the fact that user-specific credentials such as shared keys exchanged in the initial handshake are exposed. This allows an attacker to hijack an ongoing session by exploiting the authentication values of users. On the other hand, Software Defined Networking (SDN) has received much attention recently due to its many advantages, such as programmability and centralization. In this paper, a scheme for securing MP-TCP is proposed. This is achieved with the assistance of SDN, in which a new security module residing in the SDN controller acts as a third-party session-key distribution authority. After the retrieval of session keys, a lightweight information-hiding mechanism to secure the keys exchanged during the initial handshake is proposed.

Read the paper · More papers on PaperTik